Skip to content

feat: add wildcard pattern support for logging header capture (e.g. x-custom-*) - #3958

Merged
akshaydeo merged 1 commit into
devfrom
06-01-feat_support_wildcard_on_request_headers
Jun 3, 2026
Merged

feat: add wildcard pattern support for logging header capture (e.g. x-custom-*)#3958
akshaydeo merged 1 commit into
devfrom
06-01-feat_support_wildcard_on_request_headers

Conversation

@BearTS

@BearTS BearTS commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds wildcard pattern support to the logging headers configuration, allowing users to capture groups of headers by prefix (e.g. x-custom-*) or all headers at once using *, rather than only exact header name matches.

Changes

  • Introduced loggingHeaderMatchesPattern to handle exact matches, trailing wildcard (x-custom-*), and bare wildcard (*) patterns against incoming header names
  • Updated captureLoggingHeaders to iterate over all request headers and match each against configured patterns, replacing the previous single-key lookup
  • Updated the UI description and placeholder text to document wildcard support

Type of change

  • Bug fix
  • Feature
  • Refactor
  • Documentation
  • Chore/CI

Affected areas

  • Core (Go)
  • Transports (HTTP)
  • Providers/Integrations
  • Plugins
  • UI (React)
  • Docs

How to test

Configure logging headers with a wildcard pattern such as x-custom-* or * and send requests with matching headers. Verify that the captured headers appear in the metadata field of log entries.

go test ./plugins/logging/...

cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build

Screenshots/Recordings

Before: Placeholder showed X-Tenant-ID, X-Request-Source, X-Correlation-ID with no mention of wildcard support.

After: Placeholder shows X-Tenant-ID, X-Request-Source, x-custom-* and the description explains exact names, prefix wildcards, and the bare * option.

Breaking changes

  • Yes
  • No

Related issues

Security considerations

Using * as a logging header pattern will capture all request headers, which may include sensitive values such as Authorization or session tokens. Users should be aware of the PII and secrets exposure risk when enabling broad wildcard patterns, and ensure log storage is appropriately access-controlled.

Checklist

  • I read docs/contributing/README.md and followed the guidelines
  • I added/updated tests where appropriate
  • I updated documentation where needed
  • I verified builds succeed (Go and UI)
  • I verified the CI pipeline passes locally if applicable

Summary by CodeRabbit

  • New Features

    • Logging headers configuration now supports wildcard patterns (e.g., x-custom-*, *) as well as exact names.
    • Request headers matching configured patterns are automatically captured as metadata, with support for bare (*) and prefix (prefix*) wildcards.
    • Headers with the x-bf-lh- prefix are always captured.
  • Documentation

    • Clarified logging configuration help text and updated placeholder examples for header input.
    • Shortened Models section copy to “Attach descriptions and tags to specific models.”

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds wildcard pattern matching for configured logging headers (exact, *, prefix*) in the backend and updates UI help text/placeholder to document wildcard usage; also tweaks a Models subheading string in the UI.

Changes

Logging Header Wildcard Patterns

Layer / File(s) Summary
Backend wildcard pattern matching implementation
plugins/logging/main.go
New loggingHeaderMatchesPattern helper supports exact match, bare wildcard (*), and trailing-prefix patterns (prefix*) for lowercased names. captureLoggingHeaders now iterates configured patterns (lowercased/trimmed), matches them against all request header names, and adds matched header/value pairs to metadata.
Logging UI help text and placeholder update
ui/app/workspace/config/views/loggingView.tsx
Updated "Logging Headers" help text to document comma-separated header names and wildcard patterns with examples (x-custom-*, *), notes that x-bf-lh- headers are always captured, and changed the textarea placeholder to X-Tenant-ID, X-Request-Source, x-custom-*.

Model Catalog UI Text

Layer / File(s) Summary
Models subheading text replacement
ui/app/workspace/model-catalog/views/attributesTab.tsx
Replaced the subheading text under "Models" with: “Attach descriptions and tags to specific models.”

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through headers, wild and neat,
I taught them patterns, trim and sweet.
From prefix blooms to every star (*),
UI signs point to where they are.
A nibble of docs, a tiny tweak — hooray!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main feature being added: wildcard pattern support for logging header capture with a concrete example.
Description check ✅ Passed The description comprehensively covers all key template sections including summary, changes, type, affected areas, testing, screenshots, security considerations, and breaking changes acknowledgment.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 06-01-feat_support_wildcard_on_request_headers

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies"


Comment @coderabbitai help to get the list of available commands and usage tips.

@BearTS BearTS changed the title feat: support wildcard on request headers feat: add wildcard pattern support for logging header capture (e.g. x-custom-*) Jun 1, 2026

BearTS commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

@greptile-apps

greptile-apps Bot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 5/5

Safe to merge — the change is well-scoped, the matching logic is correct, and the wildcard behaviour is consistent with how header keys are stored.

The matching helper covers all three code paths correctly, header lowercasing is handled consistently between the transport layer and the new pattern loop, the UI preserves E2E test identifiers, and no existing behaviour is regressed.

No files require special attention.

Important Files Changed

Filename Overview
plugins/logging/main.go Adds loggingHeaderMatchesPattern and updates captureLoggingHeaders to iterate all headers and match against configured patterns; logic is correct, header keys are pre-lowercased by the transport layer, and the new O(patterns x headers) loop is acceptable for typical header counts.
ui/app/workspace/config/views/loggingView.tsx Updates description text and placeholder to document wildcard pattern support; data-testid attribute preserved, no logic changes.
ui/app/workspace/model-catalog/views/attributesTab.tsx Removes 'Editorial - decoupled from pricing sync.' from the Models section description; cosmetic-only, unrelated to the wildcard feature.

Reviews (2): Last reviewed commit: "feat: support wildcard on request header..." | Re-trigger Greptile

Comment thread plugins/logging/main.go
Comment thread plugins/logging/main.go

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ui/app/workspace/config/views/loggingView.tsx`:
- Around line 237-240: Add a short security note to the header capture help text
in loggingView.tsx warning that wildcard patterns (especially "*" ) will capture
all headers including sensitive ones like Authorization/API keys; update the JSX
text block that currently describes comma-separated and wildcard header patterns
(the help text string around "Comma-separated list of request headers to
capture...") to append a concise sentence such as "Note: '*' captures all
headers — review for sensitive data before enabling." so users are explicitly
warned about possible exposure.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 39dedea0-569f-421a-9b4e-6087e324299b

📥 Commits

Reviewing files that changed from the base of the PR and between a70594c and f67aaef.

📒 Files selected for processing (2)
  • plugins/logging/main.go
  • ui/app/workspace/config/views/loggingView.tsx

Comment thread ui/app/workspace/config/views/loggingView.tsx
@BearTS
BearTS force-pushed the 06-01-feat_support_wildcard_on_request_headers branch from f67aaef to d26c778 Compare June 2, 2026 07:24

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@plugins/logging/main.go`:
- Around line 483-488: When iterating allHeaders in the wildcard scan (the loop
over for hKey, hVal := range allHeaders where
loggingHeaderMatchesPattern(pattern, hKey) is checked) skip any header whose
name starts with the normalized prefix "x-bf-lh-" so those headers are not added
again into metadata; implement a guard before creating/setting metadata that
continues the loop if strings.HasPrefix(strings.ToLower(hKey), "x-bf-lh-") (or
equivalent) to avoid duplicating headers already handled by the dedicated
normalized block.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 2ea59c8f-80e6-44ef-87a8-b8fe4c8f685e

📥 Commits

Reviewing files that changed from the base of the PR and between f67aaef and d26c778.

📒 Files selected for processing (3)
  • plugins/logging/main.go
  • ui/app/workspace/config/views/loggingView.tsx
  • ui/app/workspace/model-catalog/views/attributesTab.tsx

Comment thread plugins/logging/main.go

akshaydeo commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Merge activity

  • Jun 3, 6:54 AM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Jun 3, 6:54 AM UTC: @akshaydeo merged this pull request with Graphite.

@akshaydeo
akshaydeo merged commit 58af8be into dev Jun 3, 2026
14 checks passed
@akshaydeo
akshaydeo deleted the 06-01-feat_support_wildcard_on_request_headers branch June 3, 2026 06:54
akshaydeo pushed a commit that referenced this pull request Jun 4, 2026
…x-custom-*`) (#3958)

## Summary

Adds wildcard pattern support to the logging headers configuration, allowing users to capture groups of headers by prefix (e.g. `x-custom-*`) or all headers at once using `*`, rather than only exact header name matches.

## Changes

- Introduced `loggingHeaderMatchesPattern` to handle exact matches, trailing wildcard (`x-custom-*`), and bare wildcard (`*`) patterns against incoming header names
- Updated `captureLoggingHeaders` to iterate over all request headers and match each against configured patterns, replacing the previous single-key lookup
- Updated the UI description and placeholder text to document wildcard support

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

Configure logging headers with a wildcard pattern such as `x-custom-*` or `*` and send requests with matching headers. Verify that the captured headers appear in the `metadata` field of log entries.

```sh
go test ./plugins/logging/...

cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build
```

## Screenshots/Recordings

**Before:** Placeholder showed `X-Tenant-ID, X-Request-Source, X-Correlation-ID` with no mention of wildcard support.

**After:** Placeholder shows `X-Tenant-ID, X-Request-Source, x-custom-*` and the description explains exact names, prefix wildcards, and the bare `*` option.

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

Using `*` as a logging header pattern will capture all request headers, which may include sensitive values such as `Authorization` or session tokens. Users should be aware of the PII and secrets exposure risk when enabling broad wildcard patterns, and ensure log storage is appropriately access-controlled.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **New Features**
  * Logging headers configuration now supports wildcard patterns (e.g., `x-custom-*`, `*`) as well as exact names.
  * Request headers matching configured patterns are automatically captured as metadata, with support for bare (`*`) and prefix (`prefix*`) wildcards.
  * Headers with the `x-bf-lh-` prefix are always captured.

* **Documentation**
  * Clarified logging configuration help text and updated placeholder examples for header input.
  * Shortened Models section copy to “Attach descriptions and tags to specific models.”
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request Jun 7, 2026
akshaydeo pushed a commit that referenced this pull request Jun 7, 2026
…x-custom-*`) (#3958)

## Summary

Adds wildcard pattern support to the logging headers configuration, allowing users to capture groups of headers by prefix (e.g. `x-custom-*`) or all headers at once using `*`, rather than only exact header name matches.

## Changes

- Introduced `loggingHeaderMatchesPattern` to handle exact matches, trailing wildcard (`x-custom-*`), and bare wildcard (`*`) patterns against incoming header names
- Updated `captureLoggingHeaders` to iterate over all request headers and match each against configured patterns, replacing the previous single-key lookup
- Updated the UI description and placeholder text to document wildcard support

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

Configure logging headers with a wildcard pattern such as `x-custom-*` or `*` and send requests with matching headers. Verify that the captured headers appear in the `metadata` field of log entries.

```sh
go test ./plugins/logging/...

cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build
```

## Screenshots/Recordings

**Before:** Placeholder showed `X-Tenant-ID, X-Request-Source, X-Correlation-ID` with no mention of wildcard support.

**After:** Placeholder shows `X-Tenant-ID, X-Request-Source, x-custom-*` and the description explains exact names, prefix wildcards, and the bare `*` option.

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

Using `*` as a logging header pattern will capture all request headers, which may include sensitive values such as `Authorization` or session tokens. Users should be aware of the PII and secrets exposure risk when enabling broad wildcard patterns, and ensure log storage is appropriately access-controlled.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **New Features**
  * Logging headers configuration now supports wildcard patterns (e.g., `x-custom-*`, `*`) as well as exact names.
  * Request headers matching configured patterns are automatically captured as metadata, with support for bare (`*`) and prefix (`prefix*`) wildcards.
  * Headers with the `x-bf-lh-` prefix are always captured.

* **Documentation**
  * Clarified logging configuration help text and updated placeholder examples for header input.
  * Shortened Models section copy to “Attach descriptions and tags to specific models.”
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request Jun 7, 2026
## ✨ Features

- **OpenAI Compaction** — Added OpenAI conversation compaction support
across core, framework, logging, and the API surface (#4053)
- **Multi-Customer & Org Hierarchy** — Logs and usage tracking now
support multiple customers, teams, and business units, including
business unit CRUD, team assignment, and governance endpoints in the
OpenAPI spec (#4066, #4041, #4082)
- **Provider-Level Governance** — Budgets & limits are now scope-aware
and can be applied at the virtual-key top level and per provider, wired
from the model configs table, with UI filters for scope and providers
(#3938, #3937, #3939, #3981, #3962)
- **Customer Budgets** — Customers support multiple budgets and
`calendar_aligned` budget windows (#3998, #3997)
- **Virtual Key Attribution & Controls** — Added a `created_by` user
attribution column and a `blacklisted_models` column for virtual key
provider configs (#3672, #3653)
- **Request Header Capture** — OTel and Maxim observability plugins
capture `request_headers` by pattern, with wildcard support (e.g.
`x-custom-*`); logging gained the same wildcard header capture (#4012,
#3958)
- **OTel Content Controls & Collectors** — New `disable_content_logging`
option drops message/tool content from exported spans, plus support for
multiple OTel collectors (#4064, #3894)
- **xAI x_search** — Added xAI `x_search` tool support (#3976)
- **URL Validation** — Added fetch URL validation with private-network
configuration and link-local blocking (#3947, #3991)
- **File Scheme Pricing URLs** — Pricing source URLs now accept the
`file://` scheme for air-gapped and self-hosted deployments (#4045)
- **Paginated Virtual Keys** — Virtual key fetching is paginated to
handle deployments with very large numbers of keys (#3957)
- **Client IP Resolution** — Resolve client IP from
`X-Forwarded-For`/`X-Real-IP` headers
- **SCIM Provisioning** — Added `attributeType`/`attributeValue` SCIM
provisioning fields
- **Helm/Config Schema** — Added `roles` RBAC governance config and
`per_user_oauth` MCP auth to the Helm chart and config schema (#4004,
#4009)
- **Log Navigation UI** — Added a "View logs" menu item to customer,
team, and virtual key tables, clickable links in log detail views, a
customer detail sheet, and a reusable `BudgetDisplay` component (#4073,
#4054, #4026, #4055)
- **Faster First Paint** — Added an inline loading shell to `#root`
before React mounts (#4063)
- **Materialized View Alias** — Added an `alias` column to the
materialized view with filter support (#4078)

## 🐞 Fixed

- **Fetch URL IP Checks** — Hardened fetch URL IP checks against SSRF
(#4092)
- **Mantle Model Matching** — Broadened Mantle model matching to all
`gpt` variants (#4091)
- **Empty Thinking Blocks** — Strip thinking blocks when the signature
is empty (#4079)
- **OpenAI Stream Usage** — Removed usage from the `responses.created`
event in the OpenAI stream (#4080)
- **Prompt Cache Key** — Set the prompt cache key from the Anthropic
integration (#4086)
- **Upstream Failure Status** — Map upstream connection failures to 502
instead of 400 (#3929) (thanks
[@chris-colinsky](https://github.com/chris-colinsky)!)
- **Gemini Schema Constraints** — Accept numeric schema integer
constraints for Gemini (#3994) (thanks
[@yanhao98](https://github.com/yanhao98)!)
- **Files Provider Param** — Accept the `?provider=` query param on `GET
/v1/files` (#3971) (thanks [@alexef](https://github.com/alexef)!)
- **Optional Batch Model** — Made the `model` field optional on `POST
/v1/batches` (#3973) (thanks [@alexef](https://github.com/alexef)!)
- **Helm Azure Config** — Added missing `azure_key_config` fields to the
Helm schema (#3996) (thanks
[@axelray-dev](https://github.com/axelray-dev)!)
- **Text Completion Chunk Model** — Added the missing `Model` field to
`TextCompletionChunkResponse` (#3970) (thanks
[@kuishou68](https://github.com/kuishou68)!)
- **MCP Inline stdio Env** — MCP stdio server configs accept inline
environment variable assignments (#3861) (thanks
[@Shushmitaaaa](https://github.com/Shushmitaaaa)!)
- **Orphaned Tool Results** — Orphaned tool results in the OpenAI to
Anthropic conversion flow are no longer rejected by the Anthropic API
(#3919)
- **Node Usage Reconciliation** — Added a monotonic `inc_number` log
cursor so node usage reconciliation does not skip late async log writes
(#3664)
- **Bedrock Output Assessments** — Corrected the type of
`outputAssessments` in Bedrock responses (#4028)
- **Model Pool Pricing Reloads** — Preserve non-pricing model pool
entries across pricing reloads (#3999)
- **Ghost Node Reconciliation** — Replicate the VK hierarchy flow for
ghost node reconciliation (#4088)
- **VK Double Usage Counting** — Fixed double usage counting when
creating a virtual key (#4070)
- **Model Config Lifecycle** — Cascade deletes for model configs and
removal of stale in-memory model configs (#4051, #4043)
- **FTS Index Cap** — Reduced the FTS index `left()` cap from 800k to
250k chars to stay within the tsvector limit (#4057)
- **Sync Worker Drift** — Reduced the sync worker ticker period to 5m to
prevent threshold drift (#4023)
- **Passthrough** — Fixed passthrough budgets, gated passthrough models
per VK, model extraction for Azure passthrough, and restricted
fallbacks/provider selection to the VK boundary (#3941, #3988, #3983,
#3924)
- **Provider Response Headers** — Strip provider response headers and
add a content-type filter (#3955, #4024)
- **Stream Handling** — Drain non-SSE stream readers and retry stale
connections (#3956, #3967)
- **Azure Claude** — Strip Azure diagnostic property for Claude models
(#3925)
- **Compat max_tokens** — Preserve chat `max_tokens` during param
filtering (#3992)
- **Raw Request Flag** — Removed the raw request flag from providers
that don't support it (#4058)
- **UI Fixes** — Standardized page container layout, virtual key model
configs UI, and dashboard chart tooltips (#4046, #4052, #4044)

## 🔧 Maintenance

- **Dependency Upgrades** — Bumped transitive `golang.org/x`
dependencies (crypto, net, sys, text) for Docker Scout CVE remediation
and `recharts` to 3.8.1; cascaded version bumps across all modules
(#3900, #4003)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants